About the Role
An Overview Of This Role
As a Staff Backend Engineer on GitLab's Security Factory: Code Scanning team, you help developers find and fix security issues. Those issues live in the code they write, and you set the technical direction for the static analysis engine that finds them.
Your work spans two complementary parts of a complete security analysis. On the engine side, you shape how the static analysis toolkit models a program: parsing source into intermediate representations, resolving symbols, building call graphs, and tracking tainted data across files and languages. You define the architecture and specifications the team builds against, and you delegate component specifications within them to engineers and to the AI agents that implement them. On the evaluation side, you build and apply tooling that tests, measures, and validates what the engine finds against benchmark applications with known vulnerabilities.
What the engine can model and how we measure what it finds are parts of one picture. As a Staff engineer you hold that picture, shape the long-range technical goals of the team, and raise the bar for every engineer on it. We build the engine with AI agents that write and review code from written specifications, under human direction. We expect you to direct that work effectively and with good judgment, and to help the team do the same.
What You Do
- Act as the directly responsible individual (DRI) for the team's highest-scope initiatives from design through delivery, shipping large features with minimal guidance and shaping the long-range goals of the team.
- Bring systems built by one engineer to team ownership through documentation, tests, and shared review.
- Set the technical direction for the AI-assisted tooling that implements, reviews, and validates engine changes and findings, design the checks that decide whether an agent-written change or generated result is fit to merge, and measure detection quality against benchmark applications with known vulnerabilities, raising the bar for what counts as a trustworthy result. That includes static application security testing (SAST) rules mapped to CWE and OWASP, and the test fixtures that prove they work.
- Own the architecture of the program model (parsing, symbol resolution, intermediate representations, call graphs, and taint and data-flow analysis) and of the pipeline that turns source code into findings, and define how both extend to new languages and frameworks.
- Solve technical problems of the highest scope and complexity, actively seek out difficult impediments affecting the whole team, and advocate for improvements to quality.
Requirements
Static Analysis Expertise
You should have a strong background in static analysis techniques and tools.
AI Integration
Experience with AI-assisted tooling and its application in software development is essential.
Architecture Design
You must be skilled in designing software architecture for complex systems.
Security Knowledge
A solid understanding of security principles, including SAST, CWE, and OWASP, is required.
Nice to Have
Experience in leading engineering teams and initiatives is a plus.
Familiarity with multiple programming languages and frameworks is beneficial.
Benefits
Remote Work
Enjoy the flexibility of working remotely.
Career Development
Opportunities for professional growth and learning.
Health Insurance
Comprehensive health insurance plans are provided.